2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11468 | MEDIUM | 5.7 | 0.5% | Jan 20, 2026 | When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not b... |
| CVE-2025-66902 | HIGH | 7.5 | 0.4% | Jan 20, 2026 | An input validation issue in in Pithikos websocket-server v.0.6.4 allows a remote attacker to obtain sensitive informati... |
| CVE-2025-66692 | HIGH | 7.5 | 0.3% | Jan 20, 2026 | A buffer over-read in the PublicKey::verify() method of Binance - Trust Wallet Core before commit 5668c67 allows attacke... |
| CVE-2025-63648 | HIGH | 7.5 | 0.3% | Jan 20, 2026 | A NULL pointer dereference in the dacp_reply_playqueueedit_move function (src/httpd_dacp.c) of owntone-server commit b7e... |
| CVE-2025-63647 | HIGH | 7.5 | 0.4% | Jan 20, 2026 | A NULL pointer dereference in the parse_meta function (src/httpd_daap.c) of owntone-server commit 334beb allows attacker... |
| CVE-2025-59466 | HIGH | 7.5 | 0.6% | Jan 20, 2026 | We have identified a bug in Node.js error handling where "Maximum call stack size exceeded" errors become uncatchable wh... |
| CVE-2025-59465 | HIGH | 7.5 | 3.8% | Jan 20, 2026 | A malformed `HTTP/2 HEADERS` frame with oversized, invalid `HPACK` data can cause Node.js to crash by triggering an unha... |
| CVE-2025-59464 | HIGH | 7.5 | 0.2% | Jan 20, 2026 | A memory leak in Node.js’s OpenSSL integration occurs when converting `X.509` certificate fields to UTF-8 without freein... |
| CVE-2025-57156 | HIGH | 7.5 | 0.4% | Jan 20, 2026 | NULL pointer dereference in the dacp_reply_playqueueedit_clear function in src/httpd_dacp.c in owntone-server through co... |
| CVE-2025-57155 | HIGH | 7.5 | 0.3% | Jan 20, 2026 | NULL pointer dereference in the daap_reply_groups function in src/httpd_daap.c in owntone-server through commit 5e6f19a ... |
| CVE-2025-55132 | MEDIUM | 5.3 | 0.2% | Jan 20, 2026 | A flaw in Node.js's permission model allows a file's access and modification timestamps to be changed via `futimes()` ev... |
| CVE-2025-55131 | HIGH | 7.1 | 3.5% | Jan 20, 2026 | A flaw in Node.js's buffer allocation logic can expose uninitialized memory when allocations are interrupted, when using... |
| CVE-2025-55130 | CRITICAL | 9.1 | 1.6% | Jan 20, 2026 | A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions u... |
| CVE-2025-66803 | MEDIUM | 4.8 | 0.2% | Jan 20, 2026 | Race condition in the turbo-frame element handler in Hotwired Turbo before 8.0.x causes logout operations to fail when d... |
| CVE-2025-56005 | CRITICAL | 9.8 | 16.9% | Jan 20, 2026 | An undocumented and unsafe feature in the PLY (Python Lex-Yacc) library 3.11 allows Remote Code Execution (RCE) via the ... |
| CVE-2025-67263 | MEDIUM | 6.1 | 0.2% | Jan 20, 2026 | Abacre Retail Point of Sale 14.0.0.396 is affected by a stored cross-site scripting (XSS) vulnerability in the Clients m... |
| CVE-2025-67261 | MEDIUM | 6.5 | 0.2% | Jan 20, 2026 | Abacre Retail Point of Sale 14.0.0.396 is vulnerable to content-based blind SQL injection. The vulnerability exists in t... |
| CVE-2025-55423 | CRITICAL | 9.8 | 3.3% | Jan 20, 2026 | A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the contr... |
| CVE-2025-33233 | HIGH | 7.8 | 0.2% | Jan 20, 2026 | NVIDIA Merlin Transformers4Rec for all platforms contains a vulnerability where an attacker could cause code injection. ... |
| CVE-2025-33231 | MEDIUM | 6.7 | 0.2% | Jan 20, 2026 | NVIDIA Nsight Systems for Windows contains a vulnerability in the application’s DLL loading mechanism where an attacker ... |
| CVE-2025-33230 | HIGH | 7.3 | 1.2% | Jan 20, 2026 | NVIDIA Nsight Systems for Linux contains a vulnerability in the .run installer, where an attacker could cause an OS comm... |
| CVE-2025-33229 | HIGH | 7.3 | 0.2% | Jan 20, 2026 | NVIDIA Nsight Visual Studio for Windows contains a vulnerability in Nsight Monitor where an attacker can execute arbitra... |
| CVE-2025-33228 | HIGH | 7.3 | 1.2% | Jan 20, 2026 | NVIDIA Nsight Systems contains a vulnerability in the gfx_hotspot recipe, where an attacker could cause an OS command in... |
| CVE-2025-67824 | MEDIUM | 6.1 | 0.2% | Jan 20, 2026 | The WorklogPRO - Jira Timesheets plugin in the Jira Data Center before 4.24.2-jira9, 4.24.2-jira10 and 4.24.2-jira11 all... |
| CVE-2025-65482 | CRITICAL | 9.8 | 0.5% | Jan 20, 2026 | An XML External Entity (XXE) vulnerability in opensagres XDocReport v0.9.2 to v2.0.3 allows attackers to execute arbitra... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now